Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-769g-xf8v-jx9v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from the underlying file system by means of specifically crafted XML documents.

An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from the underlying file system by means of specifically crafted XML documents.

EPSS

Процентиль: 49%
0.00257
Низкий

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbitrary files from the underlying file system by means of specifically crafted XML documents.

EPSS

Процентиль: 49%
0.00257
Низкий

Дефекты

CWE-611